ipfw

FreeBSD IPFW NAT and Jails

IPFW in FreeBSD has built-in support for NATing and the configuration syntax is same as that of natd. It took me quite some time to figure out how to NAT for jails while ensuring that certain jails can have public IPs.

Configure the nat on one of the IP addresses:

When using stateful firewall, the NAT rule for incoming traffic must appear before check-state: Other rules (service ports) can be placed below this: Then the NAT rule for outgoing traffic: Notice above, I am NATing only traffic that comes from 10.0.0.0/8 . I allocate jails an IP on that subnet (unless I […]
December 7, 2014|Categories: FreeBSD|Tags: , , , |5 Comments
Go to Top